You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何防护Laravel/Vue应用的REST API免受恶意外部请求?

解决API Key暴露与恶意请求防护的方案(基于Laravel/Vue应用)

Alright, let's tackle this API security issue you're facing with your Laravel/Vue app. The core problem here is that static API keys embedded in frontend tracking scripts are trivial to extract via browser dev tools, and relying solely on Referer checks won't stop determined attackers—since Referer headers can be easily forged. Here are practical, Laravel-friendly solutions to harden your API against malicious requests:

1. Replace Static API Keys with Short-Lived Signed Tokens

Ditch hardcoding API keys in frontend scripts entirely. Instead, use dynamically generated, time-limited tokens:

  • When a user's site loads your tracking script, first have the frontend send a GET /api/tracking-token request. Include the user's domain (you can validate this against the initial Referer or the domain they registered with).
  • In your Laravel backend, verify the requesting domain matches the user's registered website. Then generate a random token, cache it with the user's ID and allowed domain, and set an expiration (e.g., 5 minutes).
  • The frontend uses this token instead of the API key for all subsequent tracking requests. On the backend, validate the token's validity, expiration, and that the request's origin/referer matches the cached allowed domain.

Example Laravel code for token generation:

use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Str;

public function generateTrackingToken(Request $request)
{
    $requestedDomain = parse_url($request->header('Referer'), PHP_URL_HOST);
    $user = User::where('website', $requestedDomain)->firstOrFail();
    
    $token = Str::random(64);
    Cache::put(
        "tracking:token:{$token}",
        ['user_id' => $user->id, 'allowed_domain' => $requestedDomain],
        now()->addMinutes(5)
    );
    
    return response()->json(['token' => $token]);
}

2. Implement Request Signature Verification

Add a layer of signature validation to ensure requests haven't been tampered with and come from legitimate sources:

  • Store a secret signature key in your Laravel .env (e.g., TRACKING_SIGNATURE_SECRET=your_strong_secret_here).
  • In your frontend tracking JS, generate an HMAC-SHA256 signature using the current timestamp, request body, and the secret key. Send the timestamp and signature in request headers (e.g., X-Timestamp and X-Signature).
  • On the backend:
    1. Check if the timestamp is within a valid window (e.g., 10 minutes) to prevent replay attacks.
    2. Recalculate the signature using the same logic and compare it to the incoming header.
    3. Pair this with domain validation for extra security.

Frontend JS example (using CryptoJS):

const timestamp = Math.floor(Date.now() / 1000);
const payload = { event: 'page_view', token: 'your_dynamic_token' };
const signature = CryptoJS.HmacSHA256(
    `${timestamp}&${JSON.stringify(payload)}`,
    'your_signature_secret'
).toString();

fetch('https://your-app-domain/api/track', {
    method: 'POST',
    headers: {
        'X-Timestamp': timestamp,
        'X-Signature': signature,
        'Content-Type': 'application/json'
    },
    body: JSON.stringify(payload)
});

Laravel backend validation code:

public function handleTrackingRequest(Request $request)
{
    $timestamp = $request->header('X-Timestamp');
    $receivedSignature = $request->header('X-Signature');
    
    // Block expired requests
    if (now()->timestamp - $timestamp > 600) {
        return response()->json(['error' => 'Request expired'], 403);
    }
    
    // Recalculate signature
    $calculatedSignature = hash_hmac(
        'sha256',
        "{$timestamp}&{$request->getContent()}",
        env('TRACKING_SIGNATURE_SECRET')
    );
    
    // Use hash_equals to prevent timing attacks
    if (!hash_equals($calculatedSignature, $receivedSignature)) {
        return response()->json(['error' => 'Invalid request signature'], 403);
    }
    
    // Proceed with your tracking logic...
}

3. Enforce Rate Limiting

Even if tokens or signatures are compromised, rate limiting will mitigate the impact of brute-force or spam requests:

  • Use Laravel's built-in throttle middleware to restrict request frequency per token or user. For example, limit to 100 requests per minute:
Route::post('/api/track', [TrackingController::class, 'handleTrackingRequest'])
    ->middleware('throttle:100,1');
  • For more granular control, create a custom throttle middleware that limits based on the authenticated user ID instead of IP address.

4. Strengthen Referer/Origin Validation

While Referer headers can be forged, combining them with Origin checks (more reliable in modern browsers) adds an extra layer:

  • Prioritize checking the Origin header for cross-origin requests, then fall back to Referer for same-origin or older browser requests.
  • Validate that the domain from the header exactly matches the user's registered website (include protocol checks if needed).

Laravel validation snippet:

$user = $this->getUserFromToken($request->token); // Your logic to fetch user via token
$allowedDomain = parse_url($user->website, PHP_URL_HOST);

$validOrigin = $request->header('Origin') 
    ? parse_url($request->header('Origin'), PHP_URL_HOST) === $allowedDomain 
    : false;
$validReferer = $request->header('Referer')
    ? parse_url($request->header('Referer'), PHP_URL_HOST) === $allowedDomain
    : false;

if (!$validOrigin && !$validReferer) {
    return response()->json(['error' => 'Forbidden'], 403);
}

5. Serve Dynamic, Obfuscated Tracking Scripts

Instead of having users paste raw JS with sensitive data, serve a dynamic script from your server:

  • Have users embed a simple loader script like this:
<script src="https://your-app-domain/tracking/loader?domain=user-website.com"></script>
  • Your Laravel backend generates the actual tracking JS dynamically, injecting the temporary token and signature logic on the fly. Obfuscate the script to make reverse-engineering harder.
  • This way, no sensitive keys or tokens are exposed in static frontend code—all critical logic lives on your server.

Final Recommendation

Combine dynamic short-lived tokens + request signature validation + rate limiting for the strongest defense. Start with replacing static API keys, then add signature checks, and layer in rate limiting to cover edge cases.

内容的提问来源于stack exchange,提问作者Fifciuu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:14:17